CVE-2022-40156: High severity IBM Watson Studio on Cloud Pak for Data vulnerability
REJECT DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
Other sources
A flaw was found in the XStream package. This flaw allows an attacker to cause a denial of service (DoS) in its target via XML serialization.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
— IBM
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50841 https://github.com/x-stream/xstream/issues/304
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-40156?
CVE-2022-40156 is a vulnerability in XStream that allows an attacker to cause a denial of service.
How does CVE-2022-40156 affect IBM Disconnected Log Collector?
IBM Disconnected Log Collector versions v1.0 to v1.8.2 are affected by CVE-2022-40156.
What is the severity of CVE-2022-40156?
CVE-2022-40156 has a high severity rating of 7.
How can a remote authenticated attacker exploit CVE-2022-40156?
A remote authenticated attacker can send a specially-crafted XML data to exploit CVE-2022-40156 and cause a denial of service.
Where can I find more information about CVE-2022-40156?
You can find more information about CVE-2022-40156 at the following references: [1] [2] [3]